Implementation of the Simple Network
Management Protocol (SNMP) operating on the Brocade 6547 (FC5022)
embedded switch blade, makes internal script calls to system.sh from
within the SNMP binary. An authenticated attacker could perform command
or parameter injection on SNMP operations that are only enabled on the
Brocade 6547 (FC5022) embedded switch. This injection could allow the
authenticated attacker to issue commands as Root.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Sep 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Tue, 09 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00049}

epss

{'score': 0.00056}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00045}

epss

{'score': 0.00049}


Tue, 18 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 15 Feb 2025 00:15:00 +0000

Type Values Removed Values Added
Description Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform command or parameter injection on SNMP operations that are only enabled on the Brocade 6547 (FC5022) embedded switch. This injection could allow the authenticated attacker to issue commands as Root.
Title Command or parameter injection via unique embedded switch SNMP commands.
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published:

Updated: 2025-09-09T18:59:55.320Z

Reserved: 2024-05-29T04:50:55.263Z

Link: CVE-2024-5461

cve-icon Vulnrichment

Updated: 2025-02-18T17:01:54.508Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-15T00:15:13.513

Modified: 2025-09-09T19:15:44.247

Link: CVE-2024-5461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.